Scanned pages/files
Request | Server response | Status |
http://lovelyteenssex.com/ | 200 OK Content-Length: 127891 Content-Type: text/html | clean |
http://w.sharethis.com/button/buttons.js | 200 OK Content-Length: 145774 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof(stlib)=="undefined"){var stlib={}}if(!stlib.functions){stlib.functions=[];stlib.functionCount=0}stlib.global={};stlib.global.hash=document.location.href.split("#");stlib.global.hash.shift();stlib.global.hash=stlib.global.hash.join("#");stlib.dynamicOn=true;stlib.debugOn=false;stlib.debug={count:0,messages:[],debug:function(b,a){if(a&&(typeof console)!="undefined"){console.log(b)}stlib.debug.messages.push(b)},show:function(a){for(message in stlib.debug.messages){if((typeof conso Antivirus reports:
| ||
http://lovelyteenssex.com/category/0/All/ctr/1/ | 200 OK Content-Length: 132632 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/2/ | 200 OK Content-Length: 130399 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/3/ | 200 OK Content-Length: 129944 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/4/ | 200 OK Content-Length: 130525 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/5/ | 200 OK Content-Length: 131723 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/6/ | 200 OK Content-Length: 130465 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/7/ | 200 OK Content-Length: 131220 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/8/ | 200 OK Content-Length: 130947 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/9/ | 200 OK Content-Length: 129103 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/ctr/10/ | 200 OK Content-Length: 108018 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/All/duration/1/ | 200 OK Content-Length: 132928 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/duration/1/ | 200 OK Content-Length: 131085 Content-Type: text/html | clean |
http://lovelyteenssex.com/category/0/All/duration/2/ | 200 OK Content-Length: 129084 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lovelyteenssex.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Sep 2014 21:15:27 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: from=noref; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: lfrom=noref; expires=Thu, 02-Oct-2014 21:15:27 GMT; path=/
Set-Cookie: idcheck=1411679727; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: vs=noref%7C; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: index_page=1; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
X-Powered-By: PHP/5.4.4-14+deb7u9
GET / HTTP/1.1
Host: lovelyteenssex.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Sep 2014 21:15:27 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html
Set-Cookie: from=noref; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: lfrom=noref; expires=Thu, 02-Oct-2014 21:15:27 GMT; path=/
Set-Cookie: idcheck=1411679727; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: vs=noref%7C; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
Set-Cookie: index_page=1; expires=Fri, 26-Sep-2014 21:15:27 GMT; path=/
X-Powered-By: PHP/5.4.4-14+deb7u9
Second query (visit from search engine):
GET / HTTP/1.1
Host: lovelyteenssex.com
Referer: http://www.google.com/search?q=lovelyteenssex.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lovelyteenssex.com
Referer: http://www.google.com/search?q=lovelyteenssex.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lovelyteenssex.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://lovelyteenssex.com/
Result: lovelyteenssex.com is not infected or malware details are not published yet.
Result: lovelyteenssex.com is not infected or malware details are not published yet.